CVE-2024-22186

The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator.
Configurations

No configuration.

History

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02 -

28 May 2024, 17:15

Type Values Removed Values Added
Summary (en) The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator. (en) The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator.

19 Apr 2024, 13:10

Type Values Removed Values Added
Summary
  • (es) La aplicación sufre una vulnerabilidad de escalada de privilegios. Un atacante que haya iniciado sesión como invitado puede aumentar sus privilegios envenenando la cookie para convertirse en administrador.

18 Apr 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-18 23:15

Updated : 2024-11-21 08:55


NVD link : CVE-2024-22186

Mitre link : CVE-2024-22186

CVE.ORG link : CVE-2024-22186


JSON object : View

Products Affected

No product.

CWE
CWE-565

Reliance on Cookies without Validation and Integrity Checking